CVE-2003-1438

BEA Weblogic Server - Race Condition

Title source: rule

Description

Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.

Scores

EPSS 0.0025
EPSS Percentile 48.4%

Classification

CWE
CWE-362
Status draft

Affected Products (5)

bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server

Timeline

Published Dec 31, 2003
Tracked Since Feb 18, 2026